Legal

Data Processing Agreement

Last updated: 1 July 2026

This DPA describes how iCertify processes personal data on behalf of its customers in compliance with the UK GDPR and the Data Protection Act 2018.

Scope & roles

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Controller") and iCertify Online Ltd (the "Processor").

It governs the processing of personal data that iCertify performs on your behalf when you use the platform.

Nature of processing

iCertify processes recipient and credential data solely to provide the certificate issuance, hosting, and verification services you configure.

We process personal data only on your documented instructions unless required otherwise by law.

Sub-processors

We engage vetted sub-processors for infrastructure, email delivery, and analytics under contracts that impose data-protection obligations equivalent to those in this DPA.

We maintain a current list of sub-processors and will notify you of material changes.

Security measures

iCertify implements appropriate technical and organisational measures including encryption in transit and at rest, access controls, and audit logging.

We maintain a 99.99% availability target and monitor our systems continuously for security events.

International transfers

Where personal data is transferred outside the UK, we rely on appropriate safeguards such as UK International Data Transfer Agreements or Standard Contractual Clauses, as applicable.

Enterprise customers may request specific data-residency arrangements.

Data-subject rights & deletion

We assist you in responding to data-subject requests and, upon termination, will delete or return personal data as instructed.

To execute a DPA or request our sub-processor list, contact legal@icertify.online.